Which Group Manages GPOs in Microsoft Entra Domain Services?
You have a Microsoft Entra Domain Services domain named contoso.com. You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle of least privilege. To which group should you add the administrator?
Community Votes
71% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your understanding of Entra ID Managed AD-specific permission models versus traditional on-premises Active Directory groups, with the common trap being the selection of familiar legacy roles.
Managing Group Policy Objects in Microsoft Entra Domain Services requires assigning permissions to the AAD DC Administrators group to ensure compliance with the principle of least privilege. Community consensus confirms this cloud-native administrative group replaces legacy on-premises roles for GPO management.
Option E (Group Policy Creator Owners) is the most frequent incorrect choice because it traditionally provides least-privilege GPO creation in on-premises environments, but it is not applicable or supported within the Entra ID Managed AD architecture.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The AAD DC Administrators group is the designated built-in security group for performing administrative tasks on domain controllers in Microsoft Entra Domain Services. Adding the administrator to this group grants the precise permissions needed to create, edit, and link Group Policy Objects without granting excessive domain-wide control. Microsoft explicitly recommends this group for least-privilege GPO management in the managed service environment.Why the Other Options Are Wrong
Options B, C, and D represent legacy on-premises enterprise groups that grant unrestricted domain or forest-level access, directly violating the principle of least privilege. While Option E correctly limits GPO creation in traditional Active Directory, it does not exist or function as intended within Entra ID Managed AD. Relying on these traditional groups ignores the architectural differences and security boundaries enforced by the cloud-managed directory service.Community Comment Notes
Candidates frequently debated between options A and E, reflecting a common knowledge gap regarding cloud versus on-premises AD. Comment [1] accurately highlights that Entra DS operates differently and lacks the traditional Group Policy Creator Owners role, steering the correct choice toward A. Comment [3] reinforces the AAD DC Administrators designation, aligning with official Microsoft training materials. The vote distribution demonstrates that practical experience with Entra ID Managed AD significantly improves accuracy over theoretical on-premises assumptions.Official Reference
Exam Strategy
Always map administrative requirements to the specific platform's built-in role-based access control model rather than defaulting to legacy on-premises group names. Review Microsoft's official Entra ID Managed AD documentation to understand how cloud directory services abstract traditional Active Directory permission structures.